← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-0760

A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:8.61%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
Microsoft Microsoft Project 2013 Service Pack 1 (32-bit editions) (affected), 2013 Service Pack 1 (64-bit editions) (affected), 2016 (32-bit edition) (affected), 2016 (64-bit edition) (affected), 2010 Service Pack 2 (32-bit editions) (affected), 2010 Service Pack 2 (64-bit editions) (affected)
Microsoft Microsoft Office 2019 for 32-bit editions (affected), 2019 for 64-bit editions (affected), 2016 (32-bit edition) (affected), 2016 (64-bit edition) (affected), 2010 Service Pack 2 (32-bit editions) (affected), 2010 Service Pack 2 (64-bit editions) (affected), 2013 RT Service Pack 1 (affected), 2013 Service Pack 1 (32-bit editions) (affected), 2013 Service Pack 1 (64-bit editions) (affected)
Microsoft Office 365 ProPlus 32-bit Systems (affected), 64-bit Systems (affected)
Microsoft Microsoft Excel 2016 (32-bit edition) (affected), 2016 (64-bit edition) (affected), 2010 Service Pack 2 (32-bit editions) (affected), 2010 Service Pack 2 (64-bit editions) (affected), 2013 RT Service Pack 1 (affected), 2013 Service Pack 1 (32-bit editions) (affected), 2013 Service Pack 1 (64-bit editions) (affected)
Microsoft Microsoft PowerPoint 2016 (32-bit edition) (affected), 2016 (64-bit edition) (affected), 2010 Service Pack 2 (32-bit editions) (affected), 2010 Service Pack 2 (64-bit editions) (affected), 2013 RT Service Pack 1 (affected), 2013 Service Pack 1 (32-bit editions) (affected), 2013 Service Pack 1 (64-bit editions) (affected)
Microsoft Microsoft Visio 2016 (32-bit edition) (affected), 2016 (64-bit edition) (affected), 2010 Service Pack 2 (32-bit editions) (affected), 2010 Service Pack 2 (64-bit editions) (affected), 2013 Service Pack 1 (64-bit editions) (affected), 2013 Service Pack 1 (32-bit editions) (affected)
Microsoft Microsoft Word 2016 (32-bit edition) (affected), 2016 (64-bit edition) (affected), 2010 Service Pack 2 (32-bit editions) (affected), 2010 Service Pack 2 (64-bit editions) (affected), 2013 RT Service Pack 1 (affected), 2013 Service Pack 1 (32-bit editions) (affected), 2013 Service Pack 1 (64-bit editions) (affected)
Microsoft Microsoft Publisher 2016 (32-bit edition) unspecified (affected)
Microsoft Microsoft Publisher 2016 (64-bit edition) unspecified (affected)
Microsoft Microsoft Access 2016 (32-bit edition) (affected), 2016 (64-bit edition) (affected), 2013 Service Pack 1 (64-bit editions) (affected), 2013 Service Pack 1 (32-bit editions) (affected), 2010 Service Pack 2 (32-bit editions) (affected), 2010 Service Pack 2 (64-bit editions) (affected)
Microsoft Microsoft Outlook 2016 (32-bit edition) (affected), 2016 (64-bit edition) (affected), 2013 Service Pack 1 (32-bit editions) (affected), 2013 Service Pack 1 (64-bit editions) (affected), 2013 RT Service Pack 1 (affected), 2010 Service Pack 2 (64-bit editions) (affected), 2010 Service Pack 2 (32-bit editions) (affected)
Microsoft Microsoft Publisher 2013 Service Pack 1 (32-bit editions) unspecified (affected)
Microsoft Microsoft Publisher 2013 Service Pack 1 (64-bit editions) unspecified (affected)
Microsoft Microsoft Publisher 2010 Service Pack 2 (64-bit editions) (affected), 2010 Service Pack 2 (32-bit editions) (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
8.610%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2019-11-04T00:00:00
Published2020-04-15T15:12:40
Last Updated2024-08-04T06:11:05

LINK COPIED TO CLIPBOARD